Senior Security Engineer at Appfire #vacancy #remote

About You:

  • Degree in Computer Science, Information Security, Engineering, or equivalent experience. 
  • 5+ years of experience working in cyber security engineering and/or architecture at a software company. 
  • Experience performing security work in a multi-cloud environment is preferred. 
  • Experience with at least one vulnerability scanning tool (e.g. Qualys, Rapid7, Wiz, etc.). 
  • Experience as a pen tester for web-based applications and familiarity with the OWASP top ten vulnerability categories. 
  • Working knowledge of at least one scripting language, Python preferred, and Linux concepts/command line familiarity. 
  • Experience with basic SQL and manipulating large data files preferred. 
  • An understanding of key cryptography concepts such as symmetric/asymmetric keys, algorithms, and protocols (PKI, GPG, RSA, x509 certificates and TLS/SSL). 
  • Knowledge of common information security frameworks such as CIS, NIST, ISO 27001 & SOC 2 a plus. 
  • Ability to work effectively within a fast-paced, changing environment with high growth. 
  • A self-starter with a demonstrated ability to take initiative, who can proactively identify issues/opportunities and recommend actions. 
  • Strategic analysis, creative problem solving, and business judgment are required. 
  • Excellent interpersonal and communication skills, including writing skills. 

Job Description

Appfire is seeking a highly skilled Senior Security Engineer to join our Appfire Information Security team. This Senior Security Engineer role will report to our CISO and work within our Security Engineering & Architecture team to handle diverse security engineering and architecture related tasks for our rapidly growing company, including managing risk through a shared vision with Appfire’s business leaders.

While focusing on people, process, systems, and metrics, and keeping up with the latest threats and trends in security, you will be tasked with understanding and resolving a variety of security requirements at Appfire. You will also handle the identification of risks and recommendations for threat mitigation. Activities will include engineering and architecture focused tasks, supporting security reviews and audits, and verification of adherence to security policy (including cloud security policies).

You will be expected to engage in professional development to maintain continual growth in professional skills and knowledge essential to the position and thrive in a highly collaborative workplace and actively engage in helping create secure software applications. 

,[Collaborate with Engineering, IT Operations, and DevOps to design, engineer, and support security within our cloud environments, products, and vendor solutions, while promoting DevSecOps., Perform security assessments and penetration testing (manage and perform) on web applications, mobile clients, etc., Enforce continuous security compliance for our Cloud apps and cloud infrastructure., Review and approve controls needed to protect data and technology assets in compliance with policies, regulation, and legal requirements., Support incident response and security operations., Ensure compliance with and support our vulnerability management program, including SCA, SAST, DAST, penetration testing, and bug bounty programs., Provide expertise in the integration efforts of Appfire acquisitions and alignment to information security standards and policies., Implement and maintain information security systems and services to support the Information Security team.] Requirements: Security, Degree, OWASP, Scripting language, Python, Linux, SQL, Cryptography, Protocols, PKI, TLS, SSL, CIS, NIST, ISO, Communication skills Additionally: Wellness Days, Equity package, Private healthcare, Lunch card, Language courses, Home office, MyBenefit, Life insurance, Gym.

protocols Establishing interpersonal relationships Python gnupg Computer Science Linux OWASP Information security ssl pki Communication rapid7 SQL qualys rsa Cybersecurity Engineering algorithms cryptography

Залишити відповідь